Input validation error in FFmpeg - CVE-2013-0858

 

Input validation error in FFmpeg - CVE-2013-0858

Published: December 7, 2013 / Updated: June 8, 2025


Vulnerability identifier: #VU42293
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-0858
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The atrac3_decode_init function in libavcodec/atrac3.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via ATRAC3 data with the joint stereo coding mode set and fewer than two channels.


Affected software

FFmpeg

How to mitigate CVE-2013-0858

Install update from vendor's website.

FFmpeg - update to 1.0.4

External References

Related Security Bulletins